Method for single sign-on to external system based on configuration
Through user demand analysis, performance evaluation and security analysis, the most suitable single sign-on solution was selected, which solved the problems of unreasonable resource allocation, poor performance and security neglect in the existing technology, and achieved system optimization and security assurance.
Patent Information
- Application Number
- CN202510778222.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-09-12
AI Technical Summary
The existing method of configuring single sign-on to external systems lacks the assessment of user resources, resulting in unreasonable resource allocation, poor performance, neglect of security, affecting system operation and user experience, and making integration difficult.
Through user demand analysis, performance evaluation, comprehensive evaluation and security analysis, calculate the user resource evaluation coefficient, performance evaluation coefficient and security evaluation coefficient, select the most suitable single sign-on solution, and perform system integration and configuration.
Optimize resource allocation, improve system performance and user experience, ensure security, simplify the integration process, and reduce management costs and complexity.
Smart Images

Figure CN120639384A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network communication and security technology, and in particular to a method for logging into an external system based on a single configuration point. Background Art
[0002] With the rapid development of information technology, the number of systems used by enterprises and organizations continues to increase, and data exchange and functional integration are required between systems. Traditional identity authentication methods are difficult to meet the interoperability requirements between multiple systems. Therefore, a unified identity authentication mechanism is needed to support seamless integration and interoperability between systems.
[0003] The current method based on configuring single sign-on to external systems may have the following problems: 1. The existing method of configuring single sign-on to external systems lacks an assessment of user resources, which will lead to inaccurate estimation of key indicators such as the number of users and login frequency, resulting in irrational resource allocation, resulting in resource waste and insufficient system carrying capacity. The lack of performance evaluation may cause the selected single sign-on solution to perform poorly in actual applications, such as long login response time and poor user experience, thereby affecting user satisfaction and system availability. The lack of comprehensive evaluation may lead to the selected single sign-on solution being not suitable for actual needs, resulting in improper configuration and incomplete functions, affecting the normal operation of the system and user experience.
[0004] 2. The few existing methods for configuring single sign-on to external systems may ignore the security parameters of single sign-on to external systems without conducting a security analysis after the single sign-on solution is selected, resulting in security vulnerabilities or risks in the system, causing security issues such as user data leakage and system attacks. Failure to conduct proper analysis of system integration and configuration will lead to problems during the integration process, requiring additional time and resources to resolve integration difficulties, delaying the system's launch and commissioning. Summary of the Invention
[0005] The purpose of the present invention is to provide a method for configuring a single sign-on to an external system, which solves the problems existing in the background technology.
[0006] In order to solve the above technical problems, the present invention adopts the following technical solutions: The present invention provides a method based on configuring single sign-on to an external system, including: Step 1, user demand analysis: Before configuring single sign-on to a specified external system, obtain user data corresponding to the single sign-on to the external system, the user data including the total number of users, the average daily number of user logins within a specified time period, and the expected growth rate of the number of users, and then calculate the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of users.
[0007] Step 2: Performance evaluation: Obtain the performance indicators corresponding to each single sign-on solution. The performance indicators include the time required to repair security vulnerabilities, user login response time, and user satisfaction score, and then calculate the performance evaluation coefficient corresponding to each single sign-on solution.
[0008] Step 3. Comprehensive evaluation: Based on the user resource evaluation coefficient corresponding to single sign-on to the external system and the performance evaluation coefficient corresponding to each single sign-on solution, the comprehensive performance evaluation coefficient of each single sign-on solution corresponding to single sign-on to the external system is analyzed to confirm the selection of the single sign-on solution.
[0009] Step 4. Security Analysis: After selecting the single sign-on solution, analyze the security parameters corresponding to single sign-on to the external system. Security parameters include the number of authentication failures, the update cycle of the encryption key, and the retention period of the security log. Then, calculate the security assessment coefficient corresponding to single sign-on to the external system, and analyze whether the security assessment corresponding to single sign-on to the external system meets the configuration requirements.
[0010] Step 5. System integration and configuration: When the corresponding security assessment for single sign-on to the external system meets the configuration requirements, determine the system integration and configuration based on the selected single sign-on solution. System integration and configuration include integrating the single sign-on solution into the system and configuring single sign-on to the external system.
[0011] Step 6. Display prompt: When the single sign-on solution is selected, a prompt will be displayed if the corresponding security assessment when single-signing on to the external system does not meet the configuration requirements.
[0012] Preferably, the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of users is obtained by calculation, and the specific calculation process is as follows: standard user data corresponding to the configured single sign-on to the external system is obtained from the database, the standard user data including the standard total number of users, the standard average daily login times of users in a specified time period, and the standard expected growth rate of the number of users;
[0013] Substitute the total number of users corresponding to single sign-on to the external system, the average number of daily logins within the specified time period, and the expected growth rate of the number of users into the calculation formula Obtain the user resource evaluation coefficient α corresponding to the single sign-on to the external system in terms of users, where A, B, and C represent the total number of users corresponding to the single sign-on to the external system, the average daily login times of users in the specified time period, and the expected growth rate of the number of users, respectively; A′, B′, and C′ represent the standard total number of users, the standard average daily login times of users in the specified time period, and the standard expected growth rate of the number of users, respectively; ι1, ι2, and ι3 are the weight factors corresponding to the set total number of users, the weight factor corresponding to the average daily login times of users in the specified time period, and the weight factor corresponding to the expected growth rate of the number of users, respectively.
[0014] Preferably, the performance indicators corresponding to each single sign-on solution are obtained in the following specific process: A1. A list of security vulnerabilities corresponding to each single sign-on solution in historical data is collected, including the type, severity, and repair time of the vulnerability. Based on the repair time corresponding to each security vulnerability, i.e., the time required from the discovery of the vulnerability to the completion of the repair, an average repair time corresponding to each single sign-on solution is calculated by averaging, i.e., the time required to repair the security vulnerability.
[0015] A2. Use monitoring tools and performance testing tools to simulate each user's login behavior, record the time it takes for each user's login request to complete the system response, and calculate the average login response time for each single sign-on solution. Calculate the average response time and calculate the average login response time for each single sign-on solution, which is the user login response time.
[0016] A3. Collect user satisfaction scores for the single sign-on system through user surveys and feedback mechanisms, including user experience and ease of use. Statistically calculate the user satisfaction scores for each single sign-on solution. Calculate the average of the user satisfaction scores for each single sign-on solution to obtain the user satisfaction scores, which are the user satisfaction scores.
[0017] Preferably, the performance evaluation coefficient corresponding to each single sign-on solution is obtained by calculation, and the specific calculation process is as follows: obtaining from a database the standard performance indicators corresponding to each single sign-on solution when configuring single sign-on to an external system, the standard performance indicators including the standard time required for security vulnerability repair, the standard user login response time, and the standard user satisfaction score;
[0018] The performance evaluation coefficient αi corresponding to each single sign-on solution is obtained, where i is the number corresponding to each single sign-on solution, i=1, 2, ..., n, and n is any integer greater than 2, wherein t i 、T i d iThey represent the time required for security vulnerability repair, user login response time, and user satisfaction score corresponding to the i-th single sign-on solution, respectively. t′, T′, and d′ represent the standard time required for security vulnerability repair, standard user login response time, and standard user satisfaction score, respectively. η1, η2, and η3 are the weight factors corresponding to the set security vulnerability repair time, user login response time, and user satisfaction score, respectively.
[0019] Preferably, the analysis obtains the comprehensive performance evaluation coefficient of each single sign-on scheme corresponding to the single sign-on to the external system. The specific analysis process is as follows: the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of the user and the performance evaluation coefficient corresponding to each single sign-on scheme are substituted into the calculation formula χ i =α*π1+β i *π2, to obtain the comprehensive performance evaluation coefficient χ of each single sign-on solution corresponding to single sign-on to the external system i , where α represents the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of users, π1 and π2 are the weight factors corresponding to the set user resource evaluation coefficient and performance evaluation coefficient, respectively.
[0020] Preferably, the selection of the single sign-on scheme is confirmed, and the specific confirmation process is as follows: comparing the comprehensive performance evaluation coefficient of each single sign-on scheme corresponding to the single sign-on to the external system with a set comprehensive performance evaluation coefficient threshold; if the comprehensive performance evaluation coefficient of a certain single sign-on scheme corresponding to the single sign-on to the external system is greater than or equal to the set comprehensive performance evaluation coefficient threshold, then it is determined that the comprehensive performance corresponding to the single sign-on scheme does not meet the configuration requirements; if the comprehensive performance evaluation coefficient of a certain single sign-on scheme corresponding to the single sign-on to the external system is less than the set comprehensive performance evaluation coefficient threshold, then it is determined that the comprehensive performance corresponding to the single sign-on scheme meets the configuration requirements, thereby analyzing whether the comprehensive performance corresponding to each single sign-on scheme meets the configuration requirements;
[0021] The comprehensive performance evaluation coefficients corresponding to the single sign-on solutions whose comprehensive performance meets the configuration requirements are sorted in ascending order, and the single sign-on solution corresponding to the comprehensive performance evaluation coefficient ranked first is the selected single sign-on solution.
[0022] Preferably, the security assessment coefficient corresponding to the single sign-on to the external system is obtained by calculating the security assessment coefficient, and the specific calculation process is as follows: obtaining standard security parameters corresponding to the single sign-on to the external system from the database, the standard security parameters including the standard number of identity authentication failures, the standard update cycle of the encryption key, and the standard retention period of the security log;
[0023] By calculating the formula The security assessment coefficient ψ corresponding to single sign-on to the external system is obtained, where X, Y, and Z represent the number of authentication failure limits, the encryption key update cycle, and the security log retention period corresponding to single sign-on to the external system, respectively. X′, Y′, and Z′ represent the standard authentication failure limits, the standard encryption key update cycle, and the standard security log retention period, respectively. κ1, κ2, and κ3 are the weight factors corresponding to the set authentication failure limits, the encryption key update cycle, and the security log retention period, respectively.
[0024] Preferably, the analysis of whether the security assessment corresponding to the single sign-on to the external system meets the configuration requirements, the specific analysis process is as follows: compare the security assessment coefficient corresponding to the single sign-on to the external system with the set security assessment coefficient threshold. If the security assessment coefficient corresponding to the single sign-on to the external system is greater than or equal to the set security assessment coefficient threshold, then it is determined that the security assessment corresponding to the single sign-on to the external system meets the configuration requirements. If the security assessment coefficient corresponding to the single sign-on to the external system is less than the set security assessment coefficient threshold, then it is determined that the security assessment corresponding to the single sign-on to the external system does not meet the configuration requirements.
[0025] Preferably, the system integration and configuration are determined in the following specific process: S1. According to the requirements of the selected single sign-on solution, a single sign-on server is deployed within the single sign-on system, and the required single sign-on system components are installed and configured. According to the requirements and security policies of the single sign-on system, a user authentication method such as username and password, and multi-factor authentication is selected and configured accordingly. In addition, according to the development documents and interfaces provided by the single sign-on system, a login page within the single sign-on system is configured, thereby realizing user identity authentication and authorization.
[0026] S2. Configure the relevant information of the external system in the single sign-on system according to the documentation and guidelines provided by the single sign-on system, including the configuration of the identity provider and the mapping of user attributes, so that the single sign-on system can pass the user authentication information to the external system. After passing the user authentication information to the external system, perform end-to-end testing to ensure that users can access the external system through the single sign-on system.
[0027] The beneficial effects of the present invention are: 1. The method based on configuring single sign-on to an external system provided by the present invention can more accurately evaluate the user scale and growth trend by analyzing user needs, and configure system resources in a targeted manner to avoid resource waste or shortage, thereby optimizing resource allocation. Performance evaluation can help select the most suitable single sign-on solution, ensure that the system performs well in terms of security vulnerability repair, user response time, etc., improve system performance and user experience, and the comprehensive evaluation takes into account multiple aspects such as user needs and performance indicators, making decisions more comprehensive and objective, which is conducive to selecting the optimal single sign-on solution.
[0028] 2. The embodiment of the present invention can ensure that the selected single sign-on solution meets security requirements through security analysis, reasonably set security parameters, reduce the risk of system attacks, and ensure user data and system security. Through the system integration and configuration instructions, it can clearly guide the specific steps and methods of integrating the single sign-on solution into the system and configuring single sign-on to external systems, reducing errors and costs in the integration process and improving integration efficiency. Configuring single sign-on to external systems can simplify user management and authority control, reduce management costs and complexity, and improve the efficiency and flexibility of system management. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0030] Figure 1 Schematic diagram of the implementation steps of the present invention. DETAILED DESCRIPTION
[0031] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0032] See also Figure 1As shown, the present invention provides a method based on configuring single sign-on to an external system, the method comprising: step one, user demand analysis: before configuring single sign-on to a specified external system, obtaining user data corresponding to the single sign-on to the external system, the user data including the total number of users, the average daily number of logins by users within a specified time period, and the expected growth rate of the number of users, and then calculating the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of users.
[0033] It should be noted that we directly query the user database of the external system to obtain the accurate total number of users, send questionnaires to users, ask them about their login frequency within the specified time period, and then calculate the average daily number of users' logins within the specified time period through mean calculation. We communicate with domain experts and industry peers to obtain their expectations and opinions on future user growth, and combine opinions from multiple parties to determine the expected growth rate of the number of users.
[0034] In a specific embodiment, the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of the user is calculated, and the specific calculation process is as follows: standard user data corresponding to the configured single sign-on to the external system is obtained from the database, the standard user data including the standard total number of users, the standard average daily number of logins of users in a specified time period, and the standard expected growth rate of the number of users;
[0035] Substitute the total number of users corresponding to single sign-on to the external system, the average number of daily logins within the specified time period, and the expected growth rate of the number of users into the calculation formula Obtain the user resource evaluation coefficient α corresponding to the single sign-on to the external system in terms of users, where A, B, and C represent the total number of users corresponding to the single sign-on to the external system, the average daily login times of users in the specified time period, and the expected growth rate of the number of users, respectively; A′, B′, and C′ represent the standard total number of users, the standard average daily login times of users in the specified time period, and the standard expected growth rate of the number of users, respectively; ι1, ι2, and ι3 are the weight factors corresponding to the set total number of users, the weight factor corresponding to the average daily login times of users in the specified time period, and the weight factor corresponding to the expected growth rate of the number of users, respectively.
[0036] It should be noted that the values of ι1, ι2, and ι3 are all greater than 0 and less than 1.
[0037] It should also be noted that, based on expert opinions and historical data corresponding to single sign-on to external systems in terms of users obtained from the database, the historical data include various weight factors corresponding to various parameter indicators corresponding to single sign-on to external systems in terms of users. The various parameter indicators include the total number of users, the average daily number of user logins within a specified time period, and the expected growth rate of the number of users. By calculating the average of the various weight factors corresponding to the various parameter indicators, the weight factors corresponding to the set total number of users, the weight factors corresponding to the average daily number of user logins within a specified time period, and the weight factors corresponding to the expected growth rate of the number of users are obtained.
[0038] Step 2: Performance evaluation: Obtain the performance indicators corresponding to each single sign-on solution. The performance indicators include the time required to repair security vulnerabilities, user login response time, and user satisfaction score, and then calculate the performance evaluation coefficient corresponding to each single sign-on solution.
[0039] In a specific embodiment, the performance indicators corresponding to each single sign-on solution are obtained by the following specific acquisition process: A1. Collecting a list of security vulnerabilities corresponding to each single sign-on solution in historical data, including the type, severity, and repair time of the vulnerability, and calculating the average repair time corresponding to each security vulnerability, i.e., the time required from the discovery of the vulnerability to the completion of the repair, to obtain the average vulnerability repair time corresponding to each single sign-on solution, i.e., the time required to repair the security vulnerability;
[0040] A2. Use monitoring tools and performance testing tools to simulate each user's login behavior, record the time it takes for each user's login request to complete the system response, and calculate the average login response time for each single sign-on solution. Calculate the average response time and calculate the average login response time for each single sign-on solution, which is the user login response time.
[0041] A3. Collect user satisfaction scores for the single sign-on system through user surveys and feedback mechanisms, including user experience and ease of use. Statistically calculate the user satisfaction scores for each single sign-on solution. Calculate the average of the user satisfaction scores for each single sign-on solution to obtain the user satisfaction scores, which are the user satisfaction scores.
[0042] In a specific embodiment, the performance evaluation coefficient corresponding to each single sign-on solution is calculated, and the specific calculation process is as follows: obtaining from a database the standard performance indicators corresponding to each single sign-on solution when configuring single sign-on to an external system, the standard performance indicators including the standard time required for security vulnerability repair, the standard user login response time, and the standard user satisfaction score;
[0043] The performance evaluation coefficient αi corresponding to each single sign-on solution is obtained, where i is the number corresponding to each single sign-on solution, i=1, 2, ..., n, and n is any integer greater than 2, wherein t i 、T i d i They represent the time required for security vulnerability repair, user login response time, and user satisfaction score corresponding to the i-th single sign-on solution, respectively. t′, T′, and d′ represent the standard time required for security vulnerability repair, standard user login response time, and standard user satisfaction score, respectively. η1, η2, and η3 are the weight factors corresponding to the set security vulnerability repair time, user login response time, and user satisfaction score, respectively.
[0044] It should be noted that the values of η1, η2, and η3 are all greater than 0 and less than 1.
[0045] It should also be noted that, based on expert opinions and historical data corresponding to each single sign-on solution obtained from the database, the historical data includes weight factors corresponding to each parameter indicator corresponding to each single sign-on solution. The parameter indicators include the time required for security vulnerability repair, user login response time, and user satisfaction score. By calculating the average of the weight factors corresponding to each parameter indicator, the weight factor corresponding to the set security vulnerability repair time, the weight factor corresponding to the user login response time, and the weight factor corresponding to the user satisfaction score are obtained.
[0046] Step 3. Comprehensive evaluation: Based on the user resource evaluation coefficient corresponding to single sign-on to the external system and the performance evaluation coefficient corresponding to each single sign-on solution, the comprehensive performance evaluation coefficient of each single sign-on solution corresponding to single sign-on to the external system is analyzed to confirm the selection of the single sign-on solution.
[0047] In a specific embodiment, the analysis obtains the comprehensive performance evaluation coefficient of each single sign-on solution corresponding to the single sign-on to the external system. The specific analysis process is as follows: the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of the user and the performance evaluation coefficient corresponding to each single sign-on solution are substituted into the calculation formula χ i =α*π1+β i *π2, to obtain the comprehensive performance evaluation coefficient χ of each single sign-on solution corresponding to single sign-on to the external system i , where α represents the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of users, π1 and π2 are the weight factors corresponding to the set user resource evaluation coefficient and performance evaluation coefficient, respectively.
[0048] It should be noted that the values of π1 and π2 are both greater than 0 and less than 1.
[0049] It should also be noted that, based on expert opinions and historical data corresponding to each single sign-on scheme corresponding to single sign-on to an external system obtained from the database, the historical data includes the weight factors corresponding to each parameter indicator of each single sign-on scheme corresponding to single sign-on to an external system, and each parameter indicator includes a user resource evaluation coefficient and a performance evaluation coefficient. By calculating the average of each weight factor corresponding to each parameter indicator, the weight factor corresponding to the set user resource evaluation coefficient and the weight factor corresponding to the performance evaluation coefficient are obtained.
[0050] In a specific embodiment, the selection of the single sign-on scheme is confirmed, and the specific confirmation process is as follows: comparing the comprehensive performance evaluation coefficient of each single sign-on scheme corresponding to the single sign-on to the external system with a set comprehensive performance evaluation coefficient threshold; if the comprehensive performance evaluation coefficient of a certain single sign-on scheme corresponding to the single sign-on to the external system is greater than or equal to the set comprehensive performance evaluation coefficient threshold, then it is determined that the comprehensive performance corresponding to the single sign-on scheme does not meet the configuration requirements; if the comprehensive performance evaluation coefficient of a certain single sign-on scheme corresponding to the single sign-on to the external system is less than the set comprehensive performance evaluation coefficient threshold, then it is determined that the comprehensive performance corresponding to the single sign-on scheme meets the configuration requirements, thereby analyzing whether the comprehensive performance corresponding to each single sign-on scheme meets the configuration requirements;
[0051] The comprehensive performance evaluation coefficients corresponding to the single sign-on solutions whose comprehensive performance meets the configuration requirements are sorted in ascending order, and the single sign-on solution corresponding to the comprehensive performance evaluation coefficient ranked first is the selected single sign-on solution.
[0052] Step 4. Security Analysis: After selecting the single sign-on solution, analyze the security parameters corresponding to single sign-on to the external system. Security parameters include the number of authentication failures, the update cycle of the encryption key, and the retention period of the security log. Then, calculate the security assessment coefficient corresponding to single sign-on to the external system, and analyze whether the security assessment corresponding to single sign-on to the external system meets the configuration requirements.
[0053] In a specific embodiment, the security assessment coefficient corresponding to the single sign-on to the external system is calculated, and the specific calculation process is as follows: obtaining standard security parameters corresponding to the single sign-on to the external system from a database, the standard security parameters including a standard identity authentication failure limit, a standard encryption key update cycle, and a standard security log retention period;
[0054] By calculating the formula The security assessment coefficient ψ corresponding to single sign-on to the external system is obtained, where X, Y, and Z represent the number of authentication failure limits, the encryption key update cycle, and the security log retention period corresponding to single sign-on to the external system, respectively. X′, Y′, and Z′ represent the standard authentication failure limits, the standard encryption key update cycle, and the standard security log retention period, respectively. κ1, κ2, and κ3 are the weight factors corresponding to the set authentication failure limits, the encryption key update cycle, and the security log retention period, respectively.
[0055] It should be noted that the values of κ1, κ2, and κ3 are all greater than 0 and less than 1.
[0056] It should also be noted that, based on expert opinions and historical data corresponding to single sign-on to an external system obtained from a database, the historical data includes weight factors corresponding to various parameter indicators when single sign-on to an external system, and each parameter indicator includes the number of identity authentication failure limits, the encryption key update cycle, and the security log retention period. By calculating the average of each weight factor corresponding to each parameter indicator, the weight factor corresponding to the set number of identity authentication failure limits, the weight factor corresponding to the encryption key update cycle, and the weight factor corresponding to the security log retention period are obtained.
[0057] In a specific embodiment, the analysis of whether the security assessment corresponding to the single sign-on to the external system meets the configuration requirements is as follows: the security assessment coefficient corresponding to the single sign-on to the external system is compared with the set security assessment coefficient threshold. If the security assessment coefficient corresponding to the single sign-on to the external system is greater than or equal to the set security assessment coefficient threshold, it is determined that the security assessment corresponding to the single sign-on to the external system meets the configuration requirements. If the security assessment coefficient corresponding to the single sign-on to the external system is less than the set security assessment coefficient threshold, it is determined that the security assessment corresponding to the single sign-on to the external system does not meet the configuration requirements.
[0058] Step 5. System integration and configuration: When the corresponding security assessment for single sign-on to the external system meets the configuration requirements, determine the system integration and configuration based on the selected single sign-on solution. System integration and configuration include integrating the single sign-on solution into the system and configuring single sign-on to the external system.
[0059] In a specific embodiment, the system integration and configuration are determined as follows: S1. According to the requirements of the selected single sign-on solution, a single sign-on server is deployed within the single sign-on system, and the required single sign-on system components are installed and configured. According to the requirements and security policies of the single sign-on system, a user authentication method such as username and password, and multi-factor authentication is selected and configured accordingly. In addition, according to the development documents and interfaces provided by the single sign-on system, a login page within the single sign-on system is configured, thereby realizing user identity authentication and authorization.
[0060] S2. Configure the relevant information of the external system in the single sign-on system according to the documentation and guidelines provided by the single sign-on system, including the configuration of the identity provider and the mapping of user attributes, so that the single sign-on system can pass the user authentication information to the external system. After passing the user authentication information to the external system, perform end-to-end testing to ensure that users can access the external system through the single sign-on system.
[0061] It should be noted that deploying a single sign-on server within a system involves installing specific server software, deploying a self-developed single sign-on system, and installing and configuring the required single sign-on system components, including authentication services, identity providers, and token services.
[0062] According to the requirements of the selected single sign-on solution, including authentication method requirements, development documentation and interface requirements, corresponding configurations are performed, including authentication method configuration, login interface configuration, and security policy configuration. The single sign-on system components include identity provider, service provider, user storage system, and single sign-on protocol implementation.
[0063] Step 6. Display prompt: When the single sign-on solution is selected, a prompt will be displayed if the corresponding security assessment when single-signing on to the external system does not meet the configuration requirements.
[0064] The method based on configuring single sign-on to an external system provided by the present invention can more accurately evaluate the user scale and growth trend by analyzing user needs, configure system resources in a targeted manner, avoid resource waste or shortage, and thus optimize resource allocation. Performance evaluation can help select the most suitable single sign-on solution, ensure that the system performs well in terms of security vulnerability repair and user response time, improve system performance and user experience, and the comprehensive evaluation takes into account multiple aspects such as user needs and performance indicators, making the decision more comprehensive and objective, which is conducive to selecting the optimal single sign-on solution.
[0065] The above content is merely an example and explanation of the concept of the present invention. Those skilled in the art may make various modifications or additions to the described specific embodiments or replace them in a similar manner. As long as they do not deviate from the concept of the invention or exceed the scope defined in this specification, they should all fall within the scope of protection of the present invention.
Claims
1. A method for configuring single sign-on to an external system, characterized in that: include: Step 1: User Demand Analysis: Before configuring single sign-on to a specified external system, obtain the user data corresponding to single sign-on to the external system. The user data includes the total number of users, the average number of daily user logins within a specified time period, and the expected growth rate of the number of users. Then, calculate the user resource evaluation coefficient corresponding to the user of single sign-on to the external system. Step 2: Performance evaluation: Obtain performance indicators for each single sign-on solution, including the time required to fix security vulnerabilities, user login response time, and user satisfaction scores. Calculate the performance evaluation coefficient for each single sign-on solution. Step 3: Comprehensive evaluation: Based on the user resource evaluation coefficient corresponding to single sign-on to the external system and the performance evaluation coefficient corresponding to each single sign-on solution, the comprehensive performance evaluation coefficient of each single sign-on solution corresponding to single sign-on to the external system is analyzed and the selection of the single sign-on solution is confirmed; Step 4: Security Analysis: After selecting a single sign-on solution, analyze the security parameters for single sign-on to external systems. These parameters include the number of authentication failures, the encryption key update cycle, and the security log retention period. The security assessment coefficient for single sign-on to external systems is then calculated to determine whether the security assessment meets the configuration requirements. Step 5: System Integration and Configuration: After the corresponding security assessment for single sign-on to the external system meets the configuration requirements, determine the system integration and configuration based on the selected single sign-on solution. System integration and configuration include integrating the single sign-on solution into the system and configuring single sign-on to the external system. Step 6. Display prompt: When the single sign-on solution is selected, a prompt will be displayed if the corresponding security assessment when single-signing on to the external system does not meet the configuration requirements.
2. The method for configuring single sign-on to an external system according to claim 1, wherein: The calculation obtains the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of the user. The specific calculation process is as follows: Obtain standard user data corresponding to the configured single sign-on to the external system from the database. The standard user data includes the standard total number of users, the standard average daily login times of users in the specified time period, and the standard expected growth rate of the number of users; Substitute the total number of users corresponding to single sign-on to the external system, the average number of daily logins within the specified time period, and the expected growth rate of the number of users into the calculation formula Obtain the user resource evaluation coefficient α corresponding to the single sign-on to the external system in terms of users, where A, B, and C represent the total number of users corresponding to the single sign-on to the external system, the average daily login times of users in the specified time period, and the expected growth rate of the number of users, respectively; A′, B′, and C′ represent the standard total number of users, the standard average daily login times of users in the specified time period, and the standard expected growth rate of the number of users, respectively; ι1, ι2, and ι3 are the weight factors corresponding to the set total number of users, the weight factor corresponding to the average daily login times of users in the specified time period, and the weight factor corresponding to the expected growth rate of the number of users, respectively.
3. The method for configuring single sign-on to an external system according to claim 1, wherein: The specific acquisition process for obtaining the performance indicators corresponding to each single sign-on solution is as follows: A1. Collect a list of security vulnerabilities corresponding to each SSO solution in historical data, including vulnerability type, severity, and remediation time. Based on the remediation time corresponding to each security vulnerability (i.e., the time required from vulnerability discovery to remediation), calculate the average remediation time for each SSO solution, which is the time required to remediate the security vulnerability. A2. Use monitoring tools and performance testing tools to simulate each user's login behavior, record the time it takes for each user's login request to complete the system response, and calculate the average login response time for each single sign-on solution. Calculate the average response time and calculate the average login response time for each single sign-on solution, which is the user login response time. A3. Collect user satisfaction scores for the single sign-on system through user surveys and feedback mechanisms, including user experience and ease of use. Statistically calculate the user satisfaction scores for each single sign-on solution. Calculate the average of the user satisfaction scores for each single sign-on solution to obtain the user satisfaction scores, which are the user satisfaction scores.
4. The method for configuring single sign-on to an external system according to claim 3, wherein: The calculation results in the performance evaluation coefficient corresponding to each single sign-on solution. The specific calculation process is as follows: Obtain standard performance indicators from the database for each single sign-on solution when configuring single sign-on to external systems. These indicators include the standard time required to fix security vulnerabilities, standard user login response time, and standard user satisfaction scores. The performance evaluation coefficient αi corresponding to each single sign-on solution is obtained, where i is the number corresponding to each single sign-on solution, i=1, 2, ..., n, and n is any integer greater than 2, wherein t i 、T i d i They represent the time required for security vulnerability repair, user login response time, and user satisfaction score corresponding to the i-th single sign-on solution, respectively. t′, T′, and d′ represent the standard time required for security vulnerability repair, standard user login response time, and standard user satisfaction score, respectively. η1, η2, and η3 are the weight factors corresponding to the set security vulnerability repair time, user login response time, and user satisfaction score, respectively.
5. The method for configuring single sign-on to an external system according to claim 4, characterized in that: The analysis yields comprehensive performance evaluation coefficients for each single sign-on solution corresponding to single sign-on to an external system. The specific analysis process is as follows: Substitute the user resource evaluation coefficient corresponding to the user aspect of single sign-on to the external system and the performance evaluation coefficient corresponding to each single sign-on solution into the calculation formula χ i =α*π1+β i *π2, to obtain the comprehensive performance evaluation coefficient χ of each single sign-on solution corresponding to single sign-on to the external system i , where α represents the user resource evaluation coefficient corresponding to the single sign-on to the external system in terms of users, π1 and π2 are the weight factors corresponding to the set user resource evaluation coefficient and performance evaluation coefficient, respectively.
6. The method for configuring single sign-on to an external system according to claim 5, characterized in that: The specific confirmation process for the selection of the single sign-on solution is as follows: Compare the comprehensive performance evaluation coefficient of each single sign-on solution corresponding to single sign-on to the external system with the set comprehensive performance evaluation coefficient threshold; if the comprehensive performance evaluation coefficient of a certain single sign-on solution corresponding to single sign-on to the external system is greater than or equal to the set comprehensive performance evaluation coefficient threshold, then determine that the comprehensive performance corresponding to the single sign-on solution does not meet the configuration requirements; if the comprehensive performance evaluation coefficient of a certain single sign-on solution corresponding to single sign-on to the external system is less than the set comprehensive performance evaluation coefficient threshold, then determine that the comprehensive performance corresponding to the single sign-on solution meets the configuration requirements, thereby analyzing whether the comprehensive performance corresponding to each single sign-on solution meets the configuration requirements; The comprehensive performance evaluation coefficients corresponding to the single sign-on solutions whose comprehensive performance meets the configuration requirements are sorted in ascending order, and the single sign-on solution corresponding to the comprehensive performance evaluation coefficient ranked first is the selected single sign-on solution.
7. The method for configuring single sign-on to an external system according to claim 1, wherein: The calculation obtains the security assessment coefficient corresponding to single sign-on to the external system. The specific calculation process is as follows: Obtain standard security parameters from the database for single sign-on to external systems. These parameters include the standard limit on authentication failures, the standard update cycle for encryption keys, and the standard retention period for security logs. By calculating the formula The security assessment coefficient ψ corresponding to single sign-on to the external system is obtained, where X, Y, and Z represent the number of authentication failure limits, the encryption key update cycle, and the security log retention period corresponding to single sign-on to the external system, respectively. X′, Y′, and Z′ represent the standard authentication failure limits, the standard encryption key update cycle, and the standard security log retention period, respectively. κ1, κ2, and κ3 are the weight factors corresponding to the set authentication failure limits, the encryption key update cycle, and the security log retention period, respectively.
8. The method for configuring single sign-on to an external system according to claim 7, wherein: The security assessment corresponding to the analysis of single sign-on to the external system meets the configuration requirements. The specific analysis process is as follows: The security assessment coefficient corresponding to single sign-on to the external system is compared with the set security assessment coefficient threshold. If the security assessment coefficient corresponding to single sign-on to the external system is greater than or equal to the set security assessment coefficient threshold, it is determined that the security assessment corresponding to single sign-on to the external system meets the configuration requirements. If the security assessment coefficient corresponding to single sign-on to the external system is less than the set security assessment coefficient threshold, it is determined that the security assessment corresponding to single sign-on to the external system does not meet the configuration requirements.
9. The method for configuring single sign-on to an external system according to claim 1, wherein: The specific process of determining system integration and configuration is as follows: S1. Deploy a single sign-on server within the single sign-on system according to the requirements of the selected single sign-on solution, install and configure the required single sign-on system components, select user authentication methods such as username and password and multi-factor authentication according to the requirements and security policies of the single sign-on system, and configure them accordingly. Configure the login page within the single sign-on system according to the development documentation and interfaces provided by the single sign-on system, thereby achieving user identity authentication and authorization. S2. Configure the relevant information of the external system in the single sign-on system according to the documentation and guidelines provided by the single sign-on system, including the configuration of the identity provider and the mapping of user attributes, so that the single sign-on system can pass the user authentication information to the external system. After passing the user authentication information to the external system, perform end-to-end testing to ensure that users can access the external system through the single sign-on system.